Description
Integer overflow in the str_pad function in ext/standard/string.c in PHP before 7.0.4 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a long string, leading to a heap-based buffer overflow.
Remediation
References
Related Vulnerabilities
WordPress Plugin Ruven Toolkit Cross-Site Scripting (1.1)
Moodle Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2014-3541)
WordPress Plugin Project Status Cross-Site Scripting (1.6)
Oracle JRE CVE-2012-3342 Vulnerability (CVE-2012-3342)
Oracle Database Server CVE-2023-22074 Vulnerability (CVE-2023-22074)